# Unable to parse imported visualizations on version 5.2.0

**URL:** <https://discuss.elastic.co/t/unable-to-parse-imported-visualizations-on-version-5-2-0/74087>\
**Category:** Kibana\
**Created:** [February 6, 2017, 3:51pm UTC](https://discuss.elastic.co/t/unable-to-parse-imported-visualizations-on-version-5-2-0/74087 "2017-02-06T15:51:35Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![jmaelbrancke](https://avatars.discourse-cdn.com/v4/letter/j/df705f/32.png) [@jmaelbrancke](https://discuss.elastic.co/u/jmaelbrancke)\
**Post date:** [February 6, 2017, 3:51pm UTC](https://discuss.elastic.co/t/unable-to-parse-imported-visualizations-on-version-5-2-0/74087/1 "2017-02-06T15:51:35Z")

</div>

Hey Guys,

I just installed the new Kibana and Elasticsearch (5.2.0) on my env and got some issues with my already created dashboards.  
With the previous version 5.1.2 i did not get these errors.

What i try to do is create a vertical bar chart with x-axis:  
hostname  
severity (include pattern ERROR)  
program

Each time when i add the pattern i receive following error in Kibana:

> Visualize: [parsing\_exception] Expected [START\_OBJECT] under [size], but got a [VALUE\_NUMBER] in [5], with { line=1 & col=397 }

My visualization:

> {  
> "title":"Error logs/servers",  
> "type":"histogram",  
> "params":{  
> "shareYAxis":true,  
> "addTooltip":true,  
> "addLegend":true,  
> "legendPosition":"right",  
> "scale":"linear",  
> "mode":"stacked",  
> "times":[  
> ],  
> "addTimeMarker":false,  
> "defaultYExtents":false,  
> "setYExtents":false,  
> "yAxis":{  
> }  
> },  
> "aggs":[  
> {  
> "id":"3",  
> "enabled":true,  
> "type":"terms",  
> "schema":"segment",  
> "params":{  
> "field":"hostname.keyword",  
> "include":{  
> "pattern":""  
> },  
> "size":10,  
> "order":"desc",  
> "orderBy":"2"  
> }  
> },  
> {  
> "id":"5",  
> "enabled":true,  
> "type":"terms",  
> "schema":"split",  
> "params":{  
> "field":"severity.keyword",  
> "include":{  
> "pattern":"ERROR"  
> },  
> "size":10,  
> "order":"desc",  
> "orderBy":"2",  
> "row":true  
> }  
> },  
> {  
> "id":"4",  
> "enabled":true,  
> "type":"terms",  
> "schema":"group",  
> "params":{  
> "field":"program.keyword",  
> "size":5,  
> "order":"desc",  
> "orderBy":"2"  
> }  
> },  
> {  
> "id":"2",  
> "enabled":true,  
> "type":"count",  
> "schema":"metric",  
> "params":{  
> }  
> }  
> ],  
> "listeners":{  
> }  
> }

Any idea why i got this error on 5.2.0 and not on 5.1.2 and how to solve this?

Thx!

---

<div class="post-metadata">

**Author:** ![Brandon\_Kobel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/brandon_kobel/32/14829_2.png) [@Brandon\_Kobel](https://discuss.elastic.co/u/Brandon_Kobel)\
**Post date:** [February 6, 2017, 4:11pm UTC](https://discuss.elastic.co/t/unable-to-parse-imported-visualizations-on-version-5-2-0/74087/2 "2017-02-06T16:11:06Z")

</div>

@jmaelbrancke are you trying to create a new vertical bar chart in 5.2.0 and it's giving you this exception; or did you create a vertical bar chart in 5.1.2, upgrade to 5.2.0 and then try to view the existing chart?

---

<div class="post-metadata">

**Author:** ![jmaelbrancke](https://avatars.discourse-cdn.com/v4/letter/j/df705f/32.png) [@jmaelbrancke](https://discuss.elastic.co/u/jmaelbrancke)\
**Post date:** [February 6, 2017, 10:11pm UTC](https://discuss.elastic.co/t/unable-to-parse-imported-visualizations-on-version-5-2-0/74087/3 "2017-02-06T22:11:10Z")

</div>

@Brandon_Kobel both ways give me this error.

I don't have the problem when i create the vizualization without the include pattern.

---

<div class="post-metadata">

**Author:** ![Brandon\_Kobel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/brandon_kobel/32/14829_2.png) [@Brandon\_Kobel](https://discuss.elastic.co/u/Brandon_Kobel)\
**Post date:** [February 6, 2017, 10:52pm UTC](https://discuss.elastic.co/t/unable-to-parse-imported-visualizations-on-version-5-2-0/74087/4 "2017-02-06T22:52:37Z")

</div>

@jmaelbrancke would you please export the affected visualization and attach it?

---

<div class="post-metadata">

**Author:** ![jmaelbrancke](https://avatars.discourse-cdn.com/v4/letter/j/df705f/32.png) [@jmaelbrancke](https://discuss.elastic.co/u/jmaelbrancke)\
**Post date:** [February 7, 2017, 8:09am UTC](https://discuss.elastic.co/t/unable-to-parse-imported-visualizations-on-version-5-2-0/74087/5 "2017-02-07T08:09:08Z")

</div>

@Brandon_Kobel i'm not able to upload the json file.  
Below you can find the export.json.

> [  
> {  
> "\_id": "Error-logs-slash-servers",  
> "\_type": "visualization",  
> "\_source": {  
> "title": "Error logs/servers",  
> "visState": "{"title":"Error logs/servers","type":"histogram","params":{"shareYAxis":true,"addTooltip":true,"addLegend":true,"legendPosition":"right","scale":"linear","mode":"stacked","times":,"addTimeMarker":false,"defaultYExtents":false,"setYExtents":false,"yAxis":{}},"aggs":[{"id":"3","enabled":true,"type":"terms","schema":"segment","params":{"field":"hostname.keyword","include":{"pattern":""},"size":10,"order":"desc","orderBy":"2"}},{"id":"5","enabled":true,"type":"terms","schema":"split","params":{"field":"severity.keyword","include":{"pattern":"ERROR"},"size":10,"order":"desc","orderBy":"2","row":true}},{"id":"4","enabled":true,"type":"terms","schema":"group","params":{"field":"program.keyword","size":5,"order":"desc","orderBy":"2"}},{"id":"2","enabled":true,"type":"count","schema":"metric","params":{}}],"listeners":{}}",  
> "uiStateJSON": "{}",  
> "description": "",  
> "version": 1,  
> "kibanaSavedObjectMeta": {  
> "searchSourceJSON": "{"index":"ovs-_","query":{"query\_string":{"analyze\_wildcard":true,"query":"_"}},"filter":}"  
> }  
> }  
> }  
> ]

---

<div class="post-metadata">

**Author:** ![Brandon\_Kobel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/brandon_kobel/32/14829_2.png) [@Brandon\_Kobel](https://discuss.elastic.co/u/Brandon_Kobel)\
**Post date:** [February 7, 2017, 12:15pm UTC](https://discuss.elastic.co/t/unable-to-parse-imported-visualizations-on-version-5-2-0/74087/6 "2017-02-07T12:15:58Z")

</div>

@jmaelbrancke would you mind taking a screenshot of where you're seeing that error? I'm having trouble trying to replicate the issue that you're experiencing.

---

<div class="post-metadata">

**Author:** ![jmaelbrancke](https://avatars.discourse-cdn.com/v4/letter/j/df705f/32.png) [@jmaelbrancke](https://discuss.elastic.co/u/jmaelbrancke)\
**Post date:** [February 7, 2017, 1:30pm UTC](https://discuss.elastic.co/t/unable-to-parse-imported-visualizations-on-version-5-2-0/74087/7 "2017-02-07T13:30:42Z")

</div>

@Brandon_Kobel i added both outputs from 5.2.0 (one with the include pattern and one without) and from 5.2.1.

**Kibana 5.2.0 with include pattern**  
 ![](https://us1.discourse-cdn.com/elastic/original/2X/1/1e9bf87092a6de378e14ae7b5de67213605fbb50.png)

**Kibana 5.2.0 without include pattern**  
 ![](https://us1.discourse-cdn.com/elastic/original/2X/b/bf7c3869de0d644c3b55f535ed222af9e0f07641.png)

**Kibana 5.1.2**  
 ![](https://us1.discourse-cdn.com/elastic/original/2X/1/1897ed1b37ceda57a1cd05335849738950d82a4c.png)

---

<div class="post-metadata">

**Author:** ![Terence\_Chuen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/terence_chuen/32/13956_2.png) [@Terence\_Chuen](https://discuss.elastic.co/u/Terence_Chuen)\
**Post date:** [February 9, 2017, 7:45am UTC](https://discuss.elastic.co/t/unable-to-parse-imported-visualizations-on-version-5-2-0/74087/8 "2017-02-09T07:45:25Z")

</div>

@jmaelbrancke Hi,I have same issue,and I got same error as you.

Did you find a solution?  
I have to remove all Include and Exclude Pattern,This is very bad.

Here is my post:

> [@Include Pattern error after update kibana to 5.2.0-1](https://discuss.elastic.co/t/include-pattern-error-after-update-kibana-to-5-2-0-1/74467):
>
> I have some visualization chart using Include or Exclude Pattern,the syntax in kibana 5.1 was work normally. But when I update kibana to 5.2.0-1 yesterday,I get error,like this: Visualize: [parsing\_exception] Expected [START\_OBJECT] under [size], but got a [VALUE\_NUMBER] in [2], with { line=1 & col=338 } I juest update kibana,elasticsearch and filebeat and I confident they versions are the same. Why I get error without modify any configuration information? Did I missing something? …

---

<div class="post-metadata">

**Author:** ![jmaelbrancke](https://avatars.discourse-cdn.com/v4/letter/j/df705f/32.png) [@jmaelbrancke](https://discuss.elastic.co/u/jmaelbrancke)\
**Post date:** [February 9, 2017, 8:19am UTC](https://discuss.elastic.co/t/unable-to-parse-imported-visualizations-on-version-5-2-0/74087/9 "2017-02-09T08:19:38Z")

</div>

Hi @Terence_Chuen,

At this moment i'm waiting for a response from @Brandon_Kobel.

Grtz

---

<div class="post-metadata">

**Author:** ![Brandon\_Kobel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/brandon_kobel/32/14829_2.png) [@Brandon\_Kobel](https://discuss.elastic.co/u/Brandon_Kobel)\
**Post date:** [February 9, 2017, 12:11pm UTC](https://discuss.elastic.co/t/unable-to-parse-imported-visualizations-on-version-5-2-0/74087/10 "2017-02-09T12:11:46Z")

</div>

Apologies for the delay responding, I've had trouble replicating this behavior, but I'm checking with a few others who have more intimate knowledge of these visualizations.

---

<div class="post-metadata">

**Author:** ![jmaelbrancke](https://avatars.discourse-cdn.com/v4/letter/j/df705f/32.png) [@jmaelbrancke](https://discuss.elastic.co/u/jmaelbrancke)\
**Post date:** [February 9, 2017, 12:36pm UTC](https://discuss.elastic.co/t/unable-to-parse-imported-visualizations-on-version-5-2-0/74087/11 "2017-02-09T12:36:18Z")

</div>

No problem, take your time.

If you need extra information, debug logs, .... just ping me and i'll give it to you.

Grtz

---

<div class="post-metadata">

**Author:** ![Brandon\_Kobel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/brandon_kobel/32/14829_2.png) [@Brandon\_Kobel](https://discuss.elastic.co/u/Brandon_Kobel)\
**Post date:** [February 9, 2017, 12:39pm UTC](https://discuss.elastic.co/t/unable-to-parse-imported-visualizations-on-version-5-2-0/74087/12 "2017-02-09T12:39:33Z")

</div>

This is being caused by a known issue with 5.2.0. Elasticsearch accidentally removed support for an "outdated" way to specify Includes/Excludes that Kibana was using, and it will be added back by Elasticsearch in 5.2.1. Here's the GitHub issue for a bit more context: [https://github.com/elastic/kibana/issues/10159](https://github.com/elastic/kibana/issues/10159)

---

<div class="post-metadata">

**Author:** ![Terence\_Chuen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/terence_chuen/32/13956_2.png) [@Terence\_Chuen](https://discuss.elastic.co/u/Terence_Chuen)\
**Post date:** [February 9, 2017, 2:32pm UTC](https://discuss.elastic.co/t/unable-to-parse-imported-visualizations-on-version-5-2-0/74087/13 "2017-02-09T14:32:17Z")

</div>

Hi,@Brandon_Kobel .

I have two question:

1. According to issue #10159 on github,should I downgrade to 5.1?

2. issue #10159 suggest we should update to the new syntax,where can I found the technical documentation about new syntax?

I would like to thank you for your answer.

---

<div class="post-metadata">

**Author:** ![Brandon\_Kobel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/brandon_kobel/32/14829_2.png) [@Brandon\_Kobel](https://discuss.elastic.co/u/Brandon_Kobel)\
**Post date:** [February 9, 2017, 2:52pm UTC](https://discuss.elastic.co/t/unable-to-parse-imported-visualizations-on-version-5-2-0/74087/14 "2017-02-09T14:52:21Z")

</div>

@Terence_Chuen you could potentially downgrade to 5.1 to resolve this issue, but you'd have to downgrade Kibana/ES; or 5.2.1 should be coming out shortly that will address this issue.

Here's the ES github issue where the old/new syntax is discussed: [https://github.com/elastic/elasticsearch/issues/22933](https://github.com/elastic/elasticsearch/issues/22933). KIbana is using the old syntax of `"exclude":{"pattern":"apollo"}` where the new syntax is simply `"exclude": "apollo"`. You won't have to change anything in your visualization to get this new syntax to work, as Kibana is responsible for generating the query.

---

<div class="post-metadata">

**Author:** ![Terence\_Chuen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/terence_chuen/32/13956_2.png) [@Terence\_Chuen](https://discuss.elastic.co/u/Terence_Chuen)\
**Post date:** [February 9, 2017, 2:58pm UTC](https://discuss.elastic.co/t/unable-to-parse-imported-visualizations-on-version-5-2-0/74087/15 "2017-02-09T14:58:29Z")

</div>

Thank you very much,I will wait for the new version.

---

<div class="post-metadata">

**Author:** ![jmaelbrancke](https://avatars.discourse-cdn.com/v4/letter/j/df705f/32.png) [@jmaelbrancke](https://discuss.elastic.co/u/jmaelbrancke)\
**Post date:** [February 16, 2017, 10:22am UTC](https://discuss.elastic.co/t/unable-to-parse-imported-visualizations-on-version-5-2-0/74087/16 "2017-02-16T10:22:41Z")

</div>

Hi @Brandon_Kobel,

I installed the new 5.2.1 Elasticsearch and Kibana like you recommended but i still receive the same error:

> Error Visualize: [parsing\_exception] Expected [START\_OBJECT] under [size], but got a [VALUE\_NUMBER] in [5], with { line=1 & col=397 }

I did not change anything to my visualizations.

Elasticsearch and Kibana version:

> dpkg -l | grep -E "(kibana|elasticsearch)"  
> ii elasticsearch 5.2.1 all Elasticsearch is a distributed RESTful search engine built for the cloud. Reference documentation can be found at [Elasticsearch Guide [8.11] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/index.html) and the 'Elasticsearch: The Definitive Guide' book can be found at [Elasticsearch: The Definitive Guide [2.x] | Elastic](https://www.elastic.co/guide/en/elasticsearch/guide/current/index.html)  
> ii kibana 5.2.1 amd64 Explore and visualize your Elasticsearch data

screenshot from Kibana when i try to add the include pattern:

 ![](https://us1.discourse-cdn.com/elastic/original/2X/9/90b960c042ad4cf7f6a4f36d9d1caec7558e6f7b.png)

---

<div class="post-metadata">

**Author:** ![Brandon\_Kobel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/brandon_kobel/32/14829_2.png) [@Brandon\_Kobel](https://discuss.elastic.co/u/Brandon_Kobel)\
**Post date:** [February 16, 2017, 1:21pm UTC](https://discuss.elastic.co/t/unable-to-parse-imported-visualizations-on-version-5-2-0/74087/17 "2017-02-16T13:21:04Z")

</div>

@jmaelbrancke the fix slipped from the 5.2.1 release and it's currently planed for the 5.3 release.

---

<div class="post-metadata">

**Author:** ![jmaelbrancke](https://avatars.discourse-cdn.com/v4/letter/j/df705f/32.png) [@jmaelbrancke](https://discuss.elastic.co/u/jmaelbrancke)\
**Post date:** [February 16, 2017, 1:28pm UTC](https://discuss.elastic.co/t/unable-to-parse-imported-visualizations-on-version-5-2-0/74087/18 "2017-02-16T13:28:29Z")

</div>

@Brandon_Kobel thank you for the update.  
Any idea when 5.3 will be released?

---

<div class="post-metadata">

**Author:** ![Brandon\_Kobel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/brandon_kobel/32/14829_2.png) [@Brandon\_Kobel](https://discuss.elastic.co/u/Brandon_Kobel)\
**Post date:** [February 16, 2017, 5:43pm UTC](https://discuss.elastic.co/t/unable-to-parse-imported-visualizations-on-version-5-2-0/74087/19 "2017-02-16T17:43:38Z")

</div>

@jmaelbrancke unfortunately, we don't have a release date scheduled for 5.3 yet, but it's begun internal alpha testing.

---

<div class="post-metadata">

**Author:** ![avivc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/avivc/32/16501_2.png) [@avivc](https://discuss.elastic.co/u/avivc)\
**Post date:** [February 28, 2017, 7:52am UTC](https://discuss.elastic.co/t/unable-to-parse-imported-visualizations-on-version-5-2-0/74087/20 "2017-02-28T07:52:19Z")

</div>

Tnx @Brandon_Kobel for the input!  
I hope that It'll come up soon ! very useful feature 🙂  
Please comment here for any changes ( where will I see the official announcement for this issue?)  
Tnx

[Next page](https://discuss.elastic.co/t/unable-to-parse-imported-visualizations-on-version-5-2-0/74087.md?page=2)
